03 · What You Need to Know
A low-burden study can still carry high consequences outside the research setting
Research risk includes more than physical harm
Research ethics often makes physical risk easy to visualize: a drug may cause an adverse effect, a procedure may cause pain, or an intervention may produce injury. Informational and social risks can be less visible because the harm may occur only if information travels beyond its intended context.
OHRP's guidance and educational materials explicitly address privacy and data confidentiality as dimensions of participant protection. Its informed-consent materials also recognize research-related injury or harm as potentially physical, psychological, social, financial, or otherwise.
For sensitive research, asking “Is this only a survey?” can therefore be the wrong starting point. A better question is what the information could do if connected to a person.
Stigma changes the consequences of identification
Stigma can attach negative social meanings to a characteristic, diagnosis, identity, experience, or behavior. Research can become ethically sensitive when participation reveals that a person belongs, or may belong, to such a category.
Potential consequences can include damaged relationships, discrimination, reputational harm, workplace consequences, social exclusion, or threats to personal safety. The specific risks vary across communities, institutions, cultures, and jurisdictions.
A question that is relatively innocuous in one setting may therefore be consequential in another. This is another example of why research vulnerability can depend on context rather than simply on who a participant is.
Legal sensitivity adds another layer of consequence
Research may collect information about illegal conduct, immigration or residency circumstances, substance use, unlicensed work, criminal justice involvement, or other matters with potential legal implications.
The precise consequences depend heavily on jurisdiction and the nature of the information. Researchers should not make generic promises that research data can never be obtained by courts, government agencies, employers, or other parties unless the applicable legal protections actually support that statement.
Watch Out
Never promise participants “complete confidentiality” simply because the research team intends to keep data private. Legal obligations, security incidents, authorized disclosures, platform practices, or other limits may apply. Consent materials should accurately describe the protections and relevant limitations that actually exist.
Privacy and confidentiality are related but different
These terms are often used as though they mean the same thing, but distinguishing them helps researchers identify where harm can occur.
Privacy
Concerns people and the circumstances in which they are approached, observed, contacted, or asked to provide information.
Confidentiality
Concerns how information entrusted to the research team is handled, protected, used, and disclosed.
A study can protect stored data well while still compromising privacy during recruitment. For example, contacting someone through a shared family telephone with a message naming a sensitive study may reveal information before the person has even consented.
Conversely, recruitment may be discreet while weak data protections create a later confidentiality risk.
Participation itself can reveal sensitive information
Researchers naturally focus on protecting answers. Sometimes the first disclosure occurs before an answer is given.
Being seen entering a specialized research clinic, joining a study-specific online group, receiving visibly labeled mail, or appearing on a participant list may reveal something about a person's health, identity, legal circumstances, or experiences.
This means confidentiality planning should begin with the recruitment pathway. How will prospective participants be identified? How will they be contacted? What will appear in messages? Who can see appointments? What does merely responding to an invitation reveal?
Removing names does not necessarily make participants unidentifiable
Direct identifiers such as names are only one route to identification. Combinations of variables can also reveal people, particularly in small populations.
Imagine publishing a quotation attributed to “a 52-year-old female department chair from a small private university in a particular province.” No name appears, but colleagues may immediately know who the person is.
Exact occupation, location, rare diagnosis, age, institutional affiliation, detailed life history, timestamps, photographs, audio, or distinctive quotations can all contribute to identifiability depending on context.
For sensitive research, de-identification should therefore be considered in relation to the actual dataset and population rather than equated mechanically with deleting a name column.
Collecting less can be stronger protection than storing more securely
If an identifier is not needed, one of the most effective ways to prevent its disclosure is not to collect it.
Researchers should examine whether they genuinely need names, exact addresses, immigration categories, precise workplaces, detailed location data, government identifiers, identifiable photographs, IP addresses, or combinations of demographic variables.
This does not mean sensitive data should never be collected. Some research questions require them. But scientific usefulness should be distinguished from curiosity. Every sensitive variable should have a defensible role in the research.
This is also a clear example of how study design can create vulnerability through unnecessary data collection.
Access control matters because not everyone needs the same data
Even within a research team, access to identifiable information need not automatically be universal. Depending on the study, researchers may separate contact information from research responses, restrict identifiable files to personnel who require them, use coded datasets for analysis, and establish appropriate retention and destruction procedures.
The exact technical and organizational controls should correspond to the sensitivity of the information, likelihood of identification, applicable security requirements, institutional policy, and legal framework.
The central principle is proportionality: highly consequential information deserves protection calibrated to what disclosure could mean, not merely to the file size or research method.
Certificates of Confidentiality provide specific protection in the United States, but they are not magic shields
For research within their scope, U.S. Certificates of Confidentiality provide legal protections against certain compelled disclosures of identifiable, sensitive research information. OHRP's guidance explains that Certificates can help protect identifying information from compulsory legal demands.
Researchers should not interpret this as universal immunity from every possible disclosure. OHRP has emphasized that such protections do not prevent every intentional or unintentional breach and that other confidentiality mechanisms remain necessary.
Current applicability and requirements should be verified through the relevant NIH, HHS, institutional, and legal sources for the particular study. Researchers outside the United States should determine what protections and disclosure obligations apply in their own jurisdictions.
Researchers should consider downstream disclosure, not only data collection
Risk can reappear when findings are disseminated. Rich qualitative quotations, case descriptions, maps, photographs, audio, video, or highly granular demographic tables can make individuals or small communities recognizable.
Aggregation can help in some settings, but it is not universally sufficient. A table describing a subgroup of two people can be highly revealing even without names.
Researchers therefore need to ask not only “Can we collect this?” but also “Can we publish, share, archive, or reuse this in the form we are planning?”
Communities can experience stigma even when individuals are not identified
Some research findings can affect groups or communities without identifying any individual participant. SACHRP has noted that research results can create social and reputational risks, including stigmatization or discrimination, for people beyond the individual research subjects themselves.
This does not mean researchers should suppress unwelcome findings. It does mean that study design, interpretation, and reporting deserve careful attention when conclusions could stigmatize a small, identifiable, or marginalized community.
The ethical challenge is to report evidence accurately without converting legitimate findings into unnecessary or unsupported generalizations about people.